4.3
CVSSv2

CVE-2018-10994

Published: 14/05/2018 Updated: 18/06/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) prior to 1.10.1 allows XSS via a URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

signal signal-desktop

Exploits

This advisory documents proof of concept flows for manipulation the HTML tag injection vulnerability discovered in Signal Desktop Versions affected include 171, 180, 190, 1100, and 1101 ...
Signal Desktop suffers from an HTML injection vulnerability ...

Recent Articles

Signal bugs, car hack antics, the Adobe flaw you may have missed, and much more
The Register • Shaun Nichols in San Francisco • 19 May 2018

EFF wins another privacy battle, ICE chips off AI spy plan

Roundup Here's your guide to this week's infosec news beyond what we've already covered. US Customs won't getting their massive terror predicting system after all. It's reported that America's immigration cops – ICE – have abandoned its call for the development of an artificially intelligent tool that would be able to predict whether a person entering the country was secretly a terrorist, based on social networking activity. We're told it wasn't outcry over human rights or privacy concerns t...